Webhook registration. A single URL receives all event types; partners dispatch by the `eventType` field in each delivered payload. The `secret` is returned **only on first registration** (the `201` response of `PUT /webhooks`). Subsequent reads and updates exclude it — save it on receipt. To rotate, `DELETE /webhooks` then `PUT /webhooks` again.
CompanyTravelToursExperiencesTourismMarketplacePartner API
Properties
Name
Type
Description
url
string
HTTPS URL where webhook events are POSTed.
secret
string
HMAC-SHA256 signing secret. Used to verify `X-Withlocals-Signature` on delivered events. Returned only on first registration.
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://raw.githubusercontent.com/api-evangelist/withlocals/main/json-schema/withlocals-webhook-schema.json",
"title": "Webhook",
"description": "Webhook registration. A single URL receives all event types; partners\ndispatch by the `eventType` field in each delivered payload.\n\nThe `secret` is returned **only on first registration** (the `201` response\nof `PUT /webhooks`). Subsequent reads and updates exclude it — save it on\nreceipt. To rotate, `DELETE /webhooks` then `PUT /webhooks` again.\n",
"x-generated": "2026-10-09",
"x-method": "derived",
"x-generator": "derive-json-schema.py",
"x-source": "openapi/withlocals-partner-api-openapi.yml#/components/schemas/Webhook",
"type": "object",
"required": [
"url"
],
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "HTTPS URL where webhook events are POSTed."
},
"secret": {
"type": "string",
"description": "HMAC-SHA256 signing secret. Used to verify `X-Withlocals-Signature` on\ndelivered events. Returned only on first registration.\n"
}
}
}
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.